USN-1402-1: libpng vulnerability

Ubuntu Security Notice USN-1402-1

libpng vulnerability

A security issue affects these releases of Ubuntu and its
derivatives:

Ubuntu 11.10

Ubuntu 11.04

Ubuntu 10.10

Ubuntu 10.04 LTS

Ubuntu 8.04 LTS

Summary

libpng could be made to crash or run programs as your login if it
opened a specially crafted file.

Software description

libpng
- PNG (Portable Network Graphics) file library

Details

It was discovered that libpng did not properly process compressed chunks.If a user or automated system using libpng were tricked into opening aspecially crafted image, an attacker could exploit this to cause a denialof service or execute code with the privileges of the user invoking theprogram.

Update instructions

The problem can be corrected by updating your system to the following
package version: